Kentico Xperience XSS Fiasco: A Closer Look at CVE-2025-32370!
Kentico Xperience before version 13.0.178 is vulnerable to Cross Site Scripting (XSS). This exploit involves crafting a malicious SVG file, zipping it up, and then uploading it to a target URL. As a result, unsuspecting users get a surprise JavaScript alert. Because nothing says “excitement” like unexpected pop-ups!

Hot Take:
Looks like Kentico Xperience needs a little more “experience” when it comes to handling SVGs safely. Who knew triangles could be so dangerous? If only geometry class had prepared us for this kind of XSS-citing development!
Key Points:
- Kentico Xperience versions before 13.0.178 are vulnerable to XSS attacks via SVG files.
- The exploit involves crafting a malicious SVG with embedded JavaScript.
- This SVG is then zipped and uploaded through a vulnerable endpoint.
- The exploit author is Alex Messham, and the vulnerability has been assigned CVE-2025-32370.
- Successful exploitation results in an alert pop-up, demonstrating the XSS vulnerability.
Already a member? Log in here